Flexible resource access control
Abstract
One feature pertains to a device that includes memory circuits having resource groups and access control circuitry. The access control circuitry establishes a tiered resource group access control scheme where security and access control properties of each resource group are managed by at least one of a hard governor execution environment or at least one soft governor execution environment. The access control circuitry also enforces access permissions of each resource group set by at least one of the hard governor execution environment or the at least one soft governor execution environment of each resource group.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . An apparatus comprising:
one or more memory circuits including a plurality of resource groups; access control circuitry communicatively coupled to the one or more memory circuits, the access control circuitry configured to:
establish a tiered resource group access control scheme where security and access control properties of each resource group of the plurality of resource groups are managed by at least one of (a) a hard governor execution environment or (b) at least one soft governor execution environment; and
enforce access permissions of each resource group of the plurality of resource groups set by at least one of (c) the hard governor execution environment or (d) the at least one soft governor execution environment of each resource group.
2 . The apparatus of claim 1 , wherein the access control circuitry is configured to establish the tiered resource group access control scheme by being further configured to:
allow only one execution environment to claim hard governorship for each resource group of the plurality of resource groups.
3 . The apparatus of claim 2 , wherein an execution environment having hard governorship of a first resource group of the plurality of resource groups exclusively manages security and access control properties of the first resource group for execution environments of the apparatus.
4 . The apparatus of claim 1 , wherein the access control circuitry is configured to establish the tiered resource group access control scheme by being further configured to:
facilitate a hard governor execution environment of a first resource group of the plurality of resource groups to grant soft governorship of the first resource group to at least a first execution environment of the apparatus.
5 . The apparatus of claim 4 , wherein the access control circuitry is further configured to:
facilitate the at least first execution environment having soft governorship of the first resource group to manage security and access control properties of the first resource group for execution environments of the apparatus subject to revocation of its soft governorship by the hard governor execution environment.
6 . The apparatus of claim 1 , wherein the access control circuitry is configured to establish the tiered resource group access control scheme by being further configured to:
enable a first execution environment to claim secondary soft governorship of a first resource group of a plurality of resource groups when the first resource group has at least one other execution environment serving as its soft governor.
7 . The apparatus of claim 6 , wherein the access control circuitry is configured to:
establish a joint lock of the first resource group such that access permissions of the first resource group cannot be changed by the first execution environment and the at least one other execution environment serving as soft governor of the first resource group unless the first execution environment and the at least one other execution environment serving as soft governor of the first resource group agree to change the access permissions.
8 . The apparatus of claim 6 , wherein the access control circuitry is configured to:
allow the first execution environment to revoke its own soft governorship of the first resource group.
9 . The apparatus of claim 1 , wherein the access control circuitry is configured to establish the tiered resource group access control scheme by being further configured to:
allow an execution environment to claim either hard governorship or soft governorship of a first resource group of the plurality of resource groups when the first resource group does not have a hard or soft governor.
10 . The apparatus of claim 1 , wherein the access control circuitry includes access control logic and a plurality of resource group registers, and each resource group register of the plurality of resource groups is associated with a corresponding resource group of the plurality of resource groups.
11 . The apparatus of claim 10 , wherein the plurality of resource group registers each include a hard governor bit indicating whether the plurality of resource groups each have a hard governor.
12 . The apparatus of claim 10 , wherein the plurality of resource group registers each include a soft governor bit indicating whether the plurality of resource group registers have soft governors.
13 . The apparatus of claim 10 , wherein the plurality of resource group registers each include a hard governor execution environment identifier field that is populated with an identifier value of a hard governor execution environment associated with the corresponding resource group of each resource group register.
14 . The apparatus of claim 10 , wherein the plurality of resource group registers each include a soft governor execution environment identifier field that is populated with at least one identifier value of at least one soft governor execution environment associated with the corresponding resource group of each resource group register.
15 . The apparatus of claim 1 , wherein the access control circuitry is further configured to:
establish the tiered resource group access control scheme where security and access control properties of a first resource group of the plurality of resource groups are managed by a first hard governor execution environment and a first soft governor execution environment; and enforce access permissions of the first resource group set by the first hard governor execution environment and the first soft governor execution environment.
16 . A method operational at an electronic device, the method comprising:
establishing a tiered resource group access control scheme where security and access control properties of each resource group of a plurality of resource groups are managed by at least one of (a) a hard governor execution environment or (b) at least one soft governor execution environment, the electronic device having one or more memory circuits including the plurality of resource groups; and enforcing, via access control circuitry, access permissions of each resource group of the plurality of resource groups set by at least one of (c) the hard governor execution environment or (d) the at least one soft governor execution environment of each resource group.
17 . The method of claim 16 , wherein establishing the tiered resource group access control scheme includes:
allowing only one execution environment to claim hard governorship for each resource group of the plurality of resource groups.
18 . The method of claim 17 , wherein an execution environment having hard governorship of a first resource group of the plurality of resource groups exclusively manages security and access control properties of the first resource group for execution environments of the electronic device.
19 . The method of claim 16 , wherein establishing the tiered resource group access control scheme includes:
facilitating a hard governor execution environment of a first resource group of the plurality of resource groups to grant soft governorship of the first resource group to at least a first execution environment of the electronic device.
20 . The method of claim 19 , the method further comprising:
facilitating the at least first execution environment having soft governorship of the first resource group to manage security and access control properties of the first resource group for execution environments of the electronic device subject to revocation of its soft governorship by the hard governor execution environment.
21 . The method of claim 16 , wherein establishing the tiered resource group access control scheme includes:
enabling a first execution environment to claim secondary soft governorship of a first resource group of a plurality of resource groups when the first resource group has at least one other execution environment serving as its soft governor.
22 . The method of claim 21 , the method further comprising:
establishing a joint lock of the first resource group such that access permissions of the first resource group cannot be changed by the first execution environment and the at least one other execution environment serving as soft governor of the first resource group unless the first execution environment and the at least one other execution environment serving as soft governor of the first resource group agree to change the access permissions.
23 . The method of claim 21 , the method further comprising:
allowing the first execution environment to revoke its own soft governorship of the first resource group.
24 . The method of claim 16 , wherein establishing the tiered resource group access control scheme includes:
allowing an execution environment to claim either hard governorship or soft governorship of a first resource group of the plurality of resource groups when the first resource group does not have a hard or soft governor.
25 . The method of claim 16 , wherein the access control circuitry includes access control logic and a plurality of resource group registers, and each resource group register of the plurality of resource groups is associated with a corresponding resource group of the plurality of resource groups.
26 . The method of claim 25 , wherein the plurality of resource group registers each include a hard governor bit indicating whether the plurality of resource groups each have a hard governor.
27 . The method of claim 25 , wherein the plurality of resource group registers each include a soft governor bit indicating whether the plurality of resource group registers have soft governors.
28 . The method of claim 25 , wherein the plurality of resource group registers each include a hard governor execution environment identifier field that is populated with an identifier value of a hard governor execution environment associated with the corresponding resource group of each resource group register.
29 . An apparatus comprising:
means for establishing a tiered resource group access control scheme where security and access control properties of each resource group of a plurality of resource groups are managed by at least one of (a) a hard governor execution environment or (b) at least one soft governor execution environment, the apparatus having one or more memory circuits including the plurality of resource groups; and means for enforcing access permissions of each resource group of the plurality of resource groups set by at least one of (c) the hard governor execution environment or (d) the at least one soft governor execution environment of each resource group.
30 . A non-transitory computer-readable storage medium having instructions stored thereon, which when executed by at least one processor of an apparatus causes the processor to:
establish a tiered resource group access control scheme where security and access control properties of each resource group of a plurality of resource groups are managed by at least one of (a) a hard governor execution environment or (b) at least one soft governor execution environment, the apparatus having one or more memory circuits including the plurality of resource groups; and enforce, via access control circuitry, access permissions of each resource group of the plurality of resource groups set by at least one of (c) the hard governor execution environment or (d) the at least one soft governor execution environment of each resource group.Join the waitlist — get patent alerts
Track US2019334919A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.